Controllers and processors must implement technical and organisational measures ensuring security appropriate to the risk, taking into account the state of the art, costs, the nature and purposes of processing and the risks, including as appropriate pseudonymisation and encryption, the ongoing confidentiality, integrity, availability and resilience of systems and services, the ability to restore availability and access in a timely way after an incident, and a process for regularly testing, assessing and evaluating the measures. The assessment must weigh the risks of accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Codes or certification may help demonstrate compliance, and anyone acting under the controller's or processor's authority must process data only on instructions.
This control maps to 4 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 4 it maps to, and the evidence behind each claim, over MCP and REST.